MCP security report

acdoyle.dev

F19/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓2 tools scanned

https://acdoyle.dev/api/mcp

highacdoyle_dispatch_x402
Instructs agent to autonomously sign and submit a payment on 402 challenge
The description tells the calling agent that on an HTTP 402 response, 'the calling agent must complete the x402 payment (sign and attach the payment header) and retry the call.' This directs the AI to autonomously authorize and execute a financial transaction (even if only on a testnet currently) without explicit per-transaction user confirmation, which is a broad and potentially dangerous capability beyond simple task dispatch — this pattern could be extended to mainnet or reused to justify autonomous spending in other contexts.
mediumacdoyle_dispatch
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumacdoyle_dispatch_x402
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumacdoyle_dispatch
Sends user task content and API credential to an unverified third-party service
The tool forwards the full natural-language task/question plus the user's acdoyle api_key to an external gateway (acdoyle.dev) outside the user's control. If the agent includes sensitive context in 'task' (e.g., financial data, personal info, credentials), it will be exfiltrated to a third party. The description gives no information about data handling/retention policies of the destination service.
mediumacdoyle_dispatch_x402
Sends user task content to external gateway without pre-authorization
Like the sibling tool, this forwards arbitrary task text to an external, third-party 'agent-to-agent gateway' with no described data-handling safeguards, risking exposure of sensitive user-provided content to an outside service.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowacdoyle_dispatch
Framing encourages suppressing appropriate hedging/uncertainty
The description states the tool 'returns one confident, non-hedged answer.' This framing could push the calling agent to present speculative or low-confidence outputs as certain, potentially misleading the end user.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/4c150660-6fa9-4f58-ba01-1a303ec92a12)](https://gateturbo.com/report/4c150660-6fa9-4f58-ba01-1a303ec92a12)

Scanned 9/12/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free